Skip to content
Skillacrity

For the CIO and security team

Your company’s know-how stays your company’s

Skillacrity sits between your people and their AI tools, so we hold ourselves to the standard you would set. This page says plainly what we do and what we don’t.

Ownership

Your skills are your company’s intellectual property.

  • Each company gets a private library. Customer skills never leave it and never reach another customer.
  • Customer skill content is never used to train models or to improve anyone else’s library.
  • No AI vendor holds your library. A vendor sees a skill only when one of your people uses it in that vendor’s tool.
  • Admins can export the entire registry in the open SKILL.md format at any time, with every tag and audience intact.
  • When a company cancels, its data is deleted on a defined schedule.

Scanning

Every skill is checked before it can be recommended.

  • Every skill is scanned for leaked secrets and for prompt injection. Skills with scripts also get a code scan for malware and data exfiltration.
  • A skill containing a secret is rejected outright and never stored.
  • Scans fail closed: if a scan errors or cannot reach a verdict, the skill is held for review.
  • Your own admins review flagged skills from your company. Our staff do not.
  • Scanning is continuous: skills your team adds are checked again whenever a new kind of threat appears, and a skill with a serious problem is pulled from use at once.
  • Skillacrity stores and serves skill content but never runs skill code. Anything that runs, runs in the user’s own AI tool under their own permissions.

Governance

Control who sees what, without slowing people down.

  • Every skill has an audience: its author and admins only, named people, a team, or the whole company.
  • Admins set the default audience for new skills and can override any skill.
  • Optional settings: require admin approval before a skill goes company-wide, limit publishing to designated authors, and alert admins when a company-wide skill changes.
  • Every publish, merge, rollout and use is logged.
  • Each person can see which AI tools are connected to their account and disconnect them. Admins can do the same for anyone.
  • Single sign-on through SAML or OIDC, and SCIM so that people who leave lose access and their skills pass to admins.

Data handling

We keep as little as we can.

  • The text a person types that triggers a recommendation is never written to disk, logs or databases.
  • Admins see usage by skill and by person as counts only. Nobody sees task content.
  • Each skill reports two yes-or-no facts: whether it was used, and whether the task succeeded. Nothing else.
  • Our own processing, such as format conversion and the safety scan, runs on models with zero data retention. We do not hand customer skills to an AI vendor.
  • No model developed in China, or built on one, is used anywhere in the product.
  • Our staff access customer data only to resolve a support request or to improve the service, and every access is logged.
  • Hosted on Amazon Web Services in the United States.

Working with your team

What your security review will ask for.

Subprocessors

The companies that help us run the service are listed on oursubprocessor list.

Security questions

Have a security questionnaire, or want to report a problem?Email us.

Talk it through with us

We are happy to walk your IT and security team through how Skillacrity handles your data.

Email us

Choose how you’d like to write to us.